When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
{
"cna_assigner": "wolfSSL",
"cwe_ids": [
"CWE-287",
"CWE-613"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/83xxx/CVE-2026-83540.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.4.15"
},
{
"fixed": "1.6.0"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-83540.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "219644588490512202676991098277966226685",
"length": 3700
},
"id": "CVE-2026-83540-2587992d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a",
"target": {
"file": "apps/wolfsshd/auth.c",
"function": "SetupUserTokenWin"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "101779740054012997581232292582715593600",
"length": 1888
},
"id": "CVE-2026-83540-289bd88a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a",
"target": {
"file": "apps/wolfsshd/auth.c",
"function": "CheckPasswordWIN"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"278773986947901878515219790257223463581",
"303781556256632243995204003066841843085",
"256111524276311919480060390374414168529",
"28222565115541727492706819136039558009",
"266428188333279143897189354987210236181",
"234838805002562847031532065622318811057",
"204218239792715954936718796067221095646"
],
"threshold": 0.9
},
"id": "CVE-2026-83540-62113bd1",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssh/commit/9777bc5ce810d6c418a1473e9e8c40cdb0026e5a",
"target": {
"file": "apps/wolfsshd/auth.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "198346462816318677227059521403127824871",
"length": 313
},
"id": "CVE-2026-83540-6428cff6",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9",
"target": {
"file": "apps/wolfsshd/auth.c",
"function": "wolfSSHD_AuthFreeUser"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "108446564782534986208777503692222165383",
"length": 7360
},
"id": "CVE-2026-83540-954d0daa",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9",
"target": {
"file": "apps/wolfsshd/wolfsshd.c",
"function": "SHELL_Subsystem"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"267992589283405772018351752202064813697",
"126107006151320590440788775643814235923",
"7808574815104365064046612331402168791",
"287874684528232171706906644882755874247"
],
"threshold": 0.9
},
"id": "CVE-2026-83540-9a992ebd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9",
"target": {
"file": "apps/wolfsshd/auth.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"323882577220866782929120014764066400897",
"191965947403911647816825608152271133446",
"319641085095427172374837915482575675559",
"253169028308862144296152649432041788690",
"189029181797153464471304152879247416903",
"163960743321409786871494427534533470012",
"221186265729423297447196051941693262783"
],
"threshold": 0.9
},
"id": "CVE-2026-83540-bb0971c8",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9",
"target": {
"file": "apps/wolfsshd/auth.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"175655273749361429960867408506612761527",
"70312326867526094872256596546303660217",
"116259992473061313384075712652551634912",
"149883931092474113103146305430090517258",
"26008619239679591543062581103702672971",
"290361149327050745936437531667357203783",
"65478345250581612689020163900172748975",
"116864508878598680653782173959734689359",
"169100608496135348544587699387752112047",
"61111332776651411365366949475486329137",
"335235687372992853316119545607377471266",
"268811912412110267696912500072565844297",
"36179908102983162681729614520121292227",
"322080785795647375807608710047498580050",
"327599562614879003477282633691107539088"
],
"threshold": 0.9
},
"id": "CVE-2026-83540-ee4d5e2d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/wolfssl/wolfssh/commit/b6bd975ccfac6aadf29b98e35e09114bef3840a9",
"target": {
"file": "apps/wolfsshd/wolfsshd.c"
}
}
]
"2026-10-08T07:15:24Z"